Integration of Consistence library with JMS Serializer
58%
Total Score
75
100
94
75
The package has eight releases but none in the last 12 months; its latest registry release was nearly five years ago. This materially raises abandonment and compatibility risk.
No commits and no active maintainers were recorded during the last three months. Combined with the stale registry release history, this weakens confidence in ongoing maintenance.
There are no open issues and four open pull requests, but no issues or pull requests were created or merged in the last month. This is a mild sign of limited current activity.
The repository has no security policy. For a dependency intended for application integration, this leaves vulnerability reporting and response expectations unclear.
The audit analyzed the only workflow successfully and found no dangerous triggers, sinks, or audit findings. However, all 16 action references are unpinned, which leaves builds exposed to moving action revisions; the lack of a top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jms/serializer Version ~2.0|~3.0 | — | — |
consistence/consistence Version ^2.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.